Hacker Newsnew | past | comments | ask | show | jobs | submit | flowerlad's commentslogin

I wish they would make Arm64 Windows binaries a standard part of the release. Intel is on its way out.


Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.


Because other replies aren't really stating it explicitly, let me add...

The water and power utilities are themselves large distributed systems. They need communications between elements just to function properly. They don't exist in a single location where people can go locally manage them in some air-gapped, offline fashion.

There is no option of not having a communication network to monitor and manage these geographically distributed elements. The question is which communication network you would use, and how you would secure it. Whether it is telephones, radio links, or people running around as messengers, it is still a communications network.

Will some "dedicated" network be any safer? If anything, I imagine the fantasy of a private network will lead to even less security. You cannot physically secure the entire signal path. You really need to treat it as untrusted and build your security on top with encryption, authentication, authorization, etc.


> You really need to treat it as untrusted and build your security on top with encryption, authentication, authorization, etc

Infrastructure usually has a long lifetime.

Things become much more vulnerable as time rolls on e.g. we should be worried about AI hacking of smart meter firmware (hard to secure and expensive to upgrade).

Today's secure system is tomorrow's insecure system. E.g. https://news.ycombinator.com/item?id=49413320 :

  Finally, I poked at something that wasn’t connected over USB but WiFi instead, the Elgato Key Light Mini. This one turned out to be way more interesting than I expected: it’s the only one with meaningful firmware integrity protection.

  Unfortunately, while that’s an improvement over all of the other devices we’ve looked at, it protects the firmware at exactly one point in time: when an update is happening. It’s not a boot time check enforced by the bootloader or any other kind of secure boot scheme, and the updater happens to be running while everything else in the device is still operating, meaning there’s huge attack surface to try to disable that signature validation. I asked Claude to look for an exploit that might enable this, and it found a doozy


> The water and power utilities are themselves large distributed systems.

For power I can understand. For water supply it is harder to understand. Does water supply have similar characteristics to power, for example can you turn on a reservoir when there is an “outage” in another?


That explains why they are networked, not why internet access is required.

The problem of secure networking has been solved long ago but there is no incentive for OT solution architects to get it right.


In the end real reason is always cost. Connecting straight to internet is extremely cheap. Anything else is somewhat more expensive.


think about a grid responding to demand. The old model (like the titanic) had a remote manager phoning the site lead who phoned the control room who phoned the engineering room.

Remote management has clear benefits, don’t be obtuse. I totally agree on the security risks, but the benefits are obvious.


I'm not seeing why it has to be connected to the internet. Make it a private, air-gapped intranet for all (or most) of the benefits of being "connected", but with no entry point for someone sitting on another continent to turn off the water.


Are you talking about the media layer or the application layer? What would be the alternative to using the internet media layer? Every utility running their own private media ? So a duplicate network of media, as broad physically as the internet, that’s not connected to the internet? That hackers could tap into, and with poorer security, because it wouldn’t be constantly probed.


mostly, because setting up a separate network is harder.

a virtual network built upon the regular internet is much easier.

And yes, mostly done wrong


I’m glad you raised this point. What are some of the better VPNs you’ve seen for secure industrial .

I asked because of books I had read about the bad ones, where unsecured industrial control protocols were exposed wirelessly , or via vpns. And I’ve been curious if any good ones are out there .


It makes sense to have them connected for a lot of reasons.


which reasons?


In addition to remote monitoring, central control over large systems clearly has benefits: quickly and automatically spinning up a power generation in one location in response to an outage or just increased demand in another one, or conversely spooling down generation in response to a large demand spike going away (many factories need to notify the grid before starting up or shutting down), shutting down water/gas flow upstream of a detected leak, or yes, working from home, which lots of people here regularly argue is a good thing.

You could absolutely make the case that it isn't worth the risk, but that isn't the same as not having benefits.


Remote monitoring is one of them presumably


But is it completely impossible to separate the monitoring and equipment/management?

Stupid example like the equipment itself is not networked, but you could watch via a webcam and/or get metrics via image recognition.

Maybe it's safer just to have somebody work the night shift.


No, and it's not strictly impossible to correctly build out a SOC / SIEM and ingest all the logs you want and pay for the right engineers to make sure it all works correctly. But damned if anyone manages to do a great job in this area. It's too complex and too expensive, so almost everyone settles for "best effort."

A lot of problems are easy conceptually, but we can't manage to tackle them.


Sounds like a good application of mesh networks.


Not really practical when the nodes are separated by large distances.


As an American I’d like Europe to stand up to Trump. If little Iran can, so can Europe.


You can elect a Congress that will stand up to him in 2026. Step 1: continue primarying out establishment candidates from the Democratic Party, because they're largely complicit. Step 2: Vote for said non-establishment candidates in the general election.

The only challenge will be that the White House and complicit state governments are moving to disenfranchise as many people as possible before then, and likewise the White House will almost surely claim election fraud if Congress flips, and try to invalidate or even interfere with vote-counting.


The establishment Democrats are not complicit in Trump's nonsense. So don't vote for non-establishment candidates in the primary; they're more likely to lose in the general election. If you want to win in the general election, you want as many "normal" Democratic candidates as possible.


> The establishment Democrats are not complicit in Trump's nonsense

Oh yes they are! They vote to approve his cabinet picks, they campaign harder against left and progressive primary challengers than against the other party, they engage in the same insider trading as the other party, they take money from many of the same PACs and lobbying groups (Israel, AI, military-industrial complex), and...

> If you want to win in the general election, you want as many "normal" Democratic candidates as possible.

...and they continue to stick to the old strategy of "be centrist and try to flip upper-class urban moderate conservatives". This has been a proven consistent failure for 10 years now. Of course one can't expect every progressive and DSA leftist to win in November. But it's also not the 90s anymore. People still want to drain the swamp, as it were, and they don't see any hope in the establishment. They thought Trump was their anti-establishment man, but now, finally, after 10 years, they see what he really is, and there's an opportunity to really give the people what they want. And the best you can offer is more proven-failed centrism? Hell no. Schumer and Pelosi and Wasserman-Schultz and all the rest are complicit in the existential threat we face today. Primary them all out and send them to the dung heap of history.


You don't necessarily need to, because he can be played like a guitar quite easily. Just look what Iran did. Look what Europe did when Trump wanted them to join the war (nothing).

The western world has already started to adapt, building a world order without the US in the center. Trump is quite helpful here, basically driving the process. Biggest question is, who gets the best pieces, Europe, China, Russia, India? Trump's burning through political capital that was built over decades, but it's a zero sum game so he essentially sells it for cheap prices.

The US want to concentrate on themselves? Sure why not, great Britain as well was a super power not to long ago. Nothing lasts forever and we most likely see the beginning of the end of an US dominated world here.


Should Google search index be forced to be public too?


Honestly, yes it should in some form. If their index contains the actual data from the sites, and they are making that information public in one way or another, then it should be available as a downloadable dataset.


How far can we take this?

Should Boeing airplane designs be public domain since the underlying math is public domain?


I don't think that slope is as slippery as you think it is.


The subject says this is free, if so what free license are you using? If the license is unspecified it may be open source but it is not free.


Goldman Sachs projects SpaceX’s total revenue to reach $474 billion in 2030, up from $18.7 billion last year. That’s 25x in just 4 years. It shouldn’t take long to check if real growth is along this predicted trajectory. But by that time Elon Musk will have sold enough of his shares. We will pay through index funds in our 401(k).


Goldman is also the lead underwriter of the IPO as I recall, so their valuation analysis is a conflict of interest. See Morning Star, who values SpaceX as half the value they’re seeking:

https://www.morningstar.com/stocks/spacex-what-investors-nee...


An aside, but I'm still amused that Morningstar Inc., the American financial services firm, shares a name with the Morning Star, a left-wing British daily newspaper originally founded in 1930 as the Daily Worker by the Communist Party of Great Britain.

(Also, y'know, synonymous with Lucifer).


The article discusses algebraic effects but React is mentioned. Don’t make the mistake of saying thinking React is functional. See https://mckoder.medium.com/why-react-is-not-functional-b1ed1...


Orban conceded defeat. This is a model for other countries to follow.


Its the minimum you can expect in any real democracy.


If only Erdogan could do the same instead of jailing Imamoglu.


It’s called democracy


Not true. Liz Cheney hasn’t committed any crimes (as far as we know).


MVVM was invented by Microsoft for 2-way syncing in WPF. Today we know 2-way syncing is a mistake.

Who uses MVC in 2026? Pretty much every framework out there, including Java frameworks and Python frameworks and .net


You have any more sources on MVVM being a mistake?

I found WPF rather nice to work with. Same with knockout.js and Angular I don’t see much downsides.

Everyone can write bad code of course in each of them but I think it was working quite well.


When React launched in 2013, its defining idea was strict one-way data flow: parents pass data down via props, and updates happen in a clear, explicit place. Children can't mutate parent state directly; they signal changes through callbacks. The result is predictable, traceable state changes.

This contrasted with MVVM frameworks like early AngularJS, Knockout, and WPF, which relied on two-way data binding. That automatic syncing felt convenient for small apps, but at scale it often led to hidden coupling and hard-to-trace update chains.

Over time, many developers came to view pervasive two-way binding as a design mistake in complex systems. React's unidirectional model gained traction because it favored clarity and control over "magic."


Thanks GPT but I know all of that. I was expecting some eye opening new evidence because person I was asking seemed really confident and using strong words.

But that’s just generic „blablabla”. MVVM is not a mistake and is still plenty useful.


If it is useful for you then it is not a mistake. For you.


Isn't Vue also MVVM?


Yes VUE is quite a descendant of knockout.js.

People confidently write strong opinions on the internet.


I've heard many people assert that 2 way binding is a mistake, but I didn't think it was settled. It still seems simpler to me than so called uni-directional data flow.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: